CVE-2023-43507: Authenticated SQL Injection Vulnerability in ClearPass Policy Manager Web-based Management Interface
A vulnerability in the web-based management interface of ClearPass Policy Manager could allow an authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. An attacker could exploit this vulnerability to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the ClearPass Policy Manager cluster.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-43507.
What is the severity level of CVE-2023-43507?
The severity level of CVE-2023-43507 is high.
What is the affected software of CVE-2023-43507?
The affected software of CVE-2023-43507 is Arubanetworks Clearpass Policy Manager versions up to 6.9.13, 6.10.0 to 6.10.8, and 6.11.0 to 6.11.4.
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by conducting SQL injection attacks against the ClearPass Policy Manager instance.
Is there a patch available to fix CVE-2023-43507?
Yes, a patch is available to fix CVE-2023-43507. It is recommended to update the ClearPass Policy Manager software to a version that is not affected by this vulnerability.